CVE-2026-102277: Denial of Service via Quadratic Algorithmic Complexity in brace-expansion
Vulnerability ID: CVE-2026-102277
CVSS Score: 5.3
Published: 2026-09-29
An uncontrolled resource consumption vulnerability exists in the brace-expansion JavaScript library. Due to an algorithmic flaw in parsing a legacy Bash-compatibility quirk involving {a},b}-shaped expansion structures, untrusted inputs containing many trailing closing braces trigger successive full-input rescans. This behavior yields quadratic CPU time complexity and high memory overhead, allowing remote, unauthenticated attackers to cause a Denial of Service (DoS) by blocking the single-threaded Node.js event loop.
TL;DR
The brace-expansion JavaScript library suffers from an O(N^2) quadratic complexity vulnerability when parsing legacy {a},b}-shaped structures with many trailing braces. This allows remote attackers to trigger a Denial of Service by blocking the single-threaded Node.js event loop.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-400, CWE-407
- Attack Vector: Network (Remote)
- CVSS v3.1 Score: 5.3
- EPSS Score: 0.00301
- Impact: Availability (Denial of Service)
- Exploit Status: Proof-of-Concept
- KEV Status: Not Listed
Affected Systems
- Applications utilizing brace-expansion in Node.js environments for path or glob matching
- Downstream packages like minimatch and glob utilizing vulnerable versions of brace-expansion
-
brace-expansion: < 1.1.21 (Fixed in:
1.1.21) -
brace-expansion: >= 2.0.0, < 2.1.7 (Fixed in:
2.1.7) -
brace-expansion: >= 3.0.0, < 3.0.9 (Fixed in:
3.0.9) -
brace-expansion: >= 4.0.0, < 5.0.12 (Fixed in:
5.0.12)
Code Analysis
Commit: 33a5ef1
Fix: limit rewrites on v5/ESM branch
Commit: bdff773
Fix: limit rewrites on v2 branch
Commit: c55e67d
Fix: limit rewrites on v3 branch
Commit: ffdfa3e
Fix: limit rewrites on v1 branch
Mitigation Strategies
- Upgrade the brace-expansion package to a patched release version
- Sanitize user inputs to reject strings containing excessive consecutive brackets
- Implement edge WAF filtering rules to drop payloads matching patterns of excessive trailing braces
Remediation Steps:
- Locate instances of the brace-expansion library within the software dependency tree using npm audit or yarn audit.
- Force update the dependency to version 1.1.21, 2.1.7, 3.0.9, or 5.0.12 depending on the major version branch in use.
- In corporate environments where direct dependency upgrades are delayed, apply a regular expression filter at the application gateway to reject patterns like '{[^}]+}[}]{10,}.*,'.
References
Read the full report for CVE-2026-102277 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)